Find notable cyber news and cases, enriched with sources, timelines, and signals.

Signal introduces Sparse Post-Quantum Ratchet for post-quantum encrypted messaging

Security Tool/Service
First reported
Last updated
Happening score
H score 10
1 unique sources, 1 articles

Summary

Hide ▲

Signal added Sparse Post-Quantum Ratchet (SPQR) to its encrypted messaging stack, strengthening protection against quantum-computing threats and future key compromise. The update extends the platform’s existing ratchet design with post-quantum key exchange and hybrid key derivation. It matters because the new mechanism is meant to preserve forward secrecy and post-compromise security as messaging encryption faces longer-term cryptographic risk.

Related Happenings

Signal adds in-app phishing confirmations and warning messages

Security Tool/Service
First: 12.05.2026 22:40 Last: 12.05.2026 22:40 Sources 1

About this happening: **Signal** added **in-app confirmations** and **warning messages** to slow phishing and social-engineering attempts that could expose **accounts**, **chats**, and **contacts**. Th...

Suspected Russia-linked Signal phishing campaign targeting political accounts

Campaign
First: 28.04.2026 13:54 Last: 28.04.2026 13:54 Sources 1

About this happening: A **suspected Russia-linked** phishing campaign on **Signal** compromised about **300 political-sphere accounts**, exposing chats, ongoing conversations, and address books. Victim...

Latest development: 12.05.2026 22:40

Signal introduced new in-app confirmations, warning messages, and educational prompts to help users resist phishing and social engineering attempts, including bogus Signal Support lures and requests to scan QR codes or share registration codes, PINs, or recovery keys.

Timeline

  1. 03.10.2025 20:15 2 articles · 7mo ago

    Signal introduces Sparse Post-Quantum Ratchet

    Initial Disclosure

    Signal introduced Sparse Post-Quantum Ratchet (SPQR) as a new cryptographic component for its end-to-end encrypted messaging system, layering it on top of the existing double ratchet as a Triple Ratchet to refresh conversation keys, discard old ones, and derive a hybrid mixed key. The design uses post-quantum ML-KEM instead of elliptic-curve Diffie-Hellman, was developed with PQShield, AIST (Japan), and New York University, and was formally verified with ProVerif and tested with hax; the rollout is gradual, requires clients to stay updated, and will be enforced across all sessions once available to all clients.

    Show sources